CVE-2016-8855

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
19/03/2017
Last modified:
20/04/2025

Description

Cross-Site Scripting (XSS) in "/sitecore/client/Applications/List Manager/Taskpages/Contact list" in Sitecore Experience Platform 8.1 rev. 160519 (8.1 Update-3) allows remote attacks via the Name or Description parameter. This is fixed in 8.2 Update-2.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sitecore:experience_platform:8.1:rev._160519:*:*:*:*:*:*